跳到主内容

Use Casdoor as the authorization server of an MCP server

The Model Context Protocol (MCP) specification separates the authorization server from the MCP server, which is the resource server. Your MCP server doesn't have to sign users in or issue tokens: it points clients to an authorization server and validates the tokens that the authorization server issues. Casdoor can be that authorization server.

This section explains how to set this up. To manage Casdoor itself from an MCP client, see the MCP server of Casdoor instead.

How the parts work together​

What Casdoor provides​

The authorization server of an MCP server has to implement several standards. Casdoor implements all of them:

StandardEndpoint or feature
RFC 8414: OAuth 2.0 Authorization Server Metadata/.well-known/oauth-authorization-server
OpenID Connect Discovery/.well-known/openid-configuration
RFC 7591: Dynamic Client Registration/api/oauth/register
RFC 7636: PKCEAuthorization code flow
RFC 8707: Resource IndicatorsTokens whose audience is your MCP server
RFC 7517: JSON Web Key Set/.well-known/jwks, for token validation

Casdoor also provides what surrounds these standards:

  • Sign-in: Passwords, single sign-on, multi-factor authentication, WebAuthn, and Face ID
  • Users: Organizations, roles, permissions, and the user directory
  • Consent: A consent screen that lists the requested scopes with their descriptions
  • Tokens: JSON Web Token (JWT) issuance, refresh tokens, and token introspection
  • Custom scopes: Permissions that you define for your tools. See Define custom scopes
  • Application categories: The category Agent with the type MCP. See Application categories
  • Self-hosting: Casdoor is open source under the Apache 2.0 license and runs on your own infrastructure

What your MCP server does​

  1. Publish Protected Resource Metadata: Return a JSON document at /.well-known/oauth-protected-resource that names Casdoor as the authorization server.
  2. Challenge unauthenticated requests: Answer them with HTTP 401 and a WWW-Authenticate: Bearer header.
  3. Validate tokens: Verify the signature of each JWT with the JWKS of Casdoor.
  4. Check the audience: Check that the aud claim of the token is the resource URI of your server.
  5. Enforce scopes: Check that the token contains the scope that each tool requires.

Your server needs no user database, no password storage, no session management, and no OAuth 2.0 endpoints of its own.

Get started​

  1. Install Casdoor, or use Casdoor Cloud.
  2. Configure Casdoor and your MCP server.
  3. Add the token validation to your server, with examples in Python, Node.js, and Go.

See also​